Orval code generator can run attacker JavaScript on import
A bug in the Orval code-generation tool lets an attacker sneak live JavaScript into an API description file. If a developer runs Orval on that file, the malicious code runs automatically the moment the generated code is loaded, no extra step needed.
- Severity
- CriticalCVSS 4.0 · 9.3
- Fix
- Fixed in 8.21.0Fix recorded on Sep 3, 2026
- Affected versions
- before 8.21.0
- Weakness
- CWE-94Code Injection
- Exploit likelihood
- 0.61% in 30 daysEPSS, higher than 47% of known flaws
- Affects
- Orval+2 more
How it works
Orval writes an API field's default value straight into the generated code as a template string, and it does not strip out special JavaScript syntax like backticks or dollar-curly-brace expressions, so a rigged default value becomes code that runs when the generated file is opened.
What to do
Run npm ls orval in your project to see the installed version, and compare it against 8.21.0. If you generate zod schemas with enum fields that have defaults, and the spec source is not fully trusted, you are exposed.
Run this in the application environment you want to check:
npm ls orvalUpdate to Orval 8.21.0 or later with npm install orval@latest, and until you update, avoid generating code from OpenAPI specs you did not write yourself or fully vet.
Technical details
Affected software: Orval, npm, zod
Orval's zod schema generator (packages/zod/src/index.ts, function formatDefaultValue) writes an enum's default value into a module-level JavaScript template literal without encoding backticks or ${...} sequences. A spec author can set a default like v${globalThis.someFunc}w, and Orval emits that string unescaped into the generated file. Because ${...} inside a template literal is live JavaScript, the expression executes the instant the generated module is imported, no function call required.
This gives CWE-94/CWE-1336 style code injection at import time in any developer, CI, test, or application environment that loads the generated schema. Fixed in 8.21.0 by properly encoding default values.
Severity breakdown
- Attack vector Network Requires network access to the vulnerable service
- Attack complexity Low No extra steps to bypass built-in attack protections
- Required conditions None No particular deployment or execution condition is required
- Privileges required None Attacker needs no account or login
- User action None No action by another user is required
- Vulnerable system: Data exposure High Sensitive data can be exposed with serious impact
- Vulnerable system: Data changes High Protected data can be changed with serious impact
- Vulnerable system: Service disruption High The service can stop or suffer serious disruption
- Other systems: Data exposure None No additional impact beyond the vulnerable system
- Other systems: Data changes None No additional impact beyond the vulnerable system
- Other systems: Service disruption None No additional impact beyond the vulnerable system
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N Open in FIRST.org calculatorReferences
- github.com · v8.21.0 (tag) patch release notes vendor advisory
- github.com · GHSA-3575-w9fc-c2j6 vendor advisory
- nvd.nist.gov · CVE-2026-71868 vdb entry us government resource
- github.com · PR #3692 GitHub Advisory vendor advisory
- github.com · commit 8ef1bfd GitHub Advisory vendor advisory
- tenable.com · CVE-2026-71868 third party advisory vdb entry
- cvefeed.io · CVE-2026-71868 third party advisory vdb entry
- osv.dev · CVE-2026-71868 vdb entry